MAL-2025-191833
Dashboard / Malicious Package / MAL-2025-191833
MAL-2025-191833
Summary: Malicious code in pydefender (PyPI)
Details: Source: kam193 (a1e2cc2d94eff74e302118c35c34f87e76175fe507facbe21c29883960c8223e) setup.py is prepared to download and run an obfuscated batch script. While the script is not detected by any AV currently, in the sandbox analysis it reveals behaviour like adding exclusions to Windows Defender Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers. Campaign: 2025-02-pydefender Reasons (based on the campaign): - Downloads and executes a remote malicious script. - malware - The package overrides the install command in setup.py to execute malicious code during installation.
References: https://www.virustotal.com/gui/file/0877653f6a24639bb02b547c94f670597c3c0cd96df910a2ac891eaeaa9cc5f3/behavior, https://tria.ge/250301-sdh1pstrz7/behavioral1, https://app.any.run/tasks/0fbdb4f9-0497-4272-baf0-872e8d6e50bc, https://bad-packages.kam193.eu/pypi/package/pydefender
Affected packages
Package
Name: pydefender
Purl: pkg:pypi/pydefender
Affected ranges
Type: N/A
Events:
